Security
How we protect the service and customer data.
Last updated July 2026
Payments
When live payments are enabled, card details are collected by the configured payment processor’s secure components. esimterra is designed not to receive or store a full card number.
The checkout identifies the available payment method and final amount before submission. Payment confirmation identifiers may be stored with the order for support, accounting and fraud prevention.
Personal data
We limit collection to data needed for orders, delivery, account features, support, security and legal obligations. Required service providers receive only the data needed for their role.
We do not sell personal information. The privacy policy explains categories, purposes, recipients, retention and rights in more detail.
Read the privacy policyAccounts and access
Customer sign-in uses time-limited passwordless verification. Sensitive server actions validate identity and authorization again instead of trusting browser state alone.
Administrative access is separated from customer access, protected with least-privilege controls and audited where the application records a privileged action.
Infrastructure
The application uses encrypted HTTPS connections, server-side secret storage and database access rules. Supplier credentials and service-role keys stay out of browser bundles and public responses.
No system is perfectly secure. Controls, dependencies and incident procedures must continue to be reviewed as the service moves from mock integrations to production.
Report a security issue
Send a clear description and safe reproduction steps to security@esimterra.com. Do not access other customers’ data, disrupt the service or include live credentials in the report.
Email support